Method and device for preventing loss of computing power of intelligent computing cloud platform
By collecting historical data from the intelligent computing cloud platform, a multi-engine detection system was constructed to trace the entire attack path, solving the problem of preventing the loss of computing power on the intelligent computing cloud platform. This achieved efficient and accurate computing power protection, improving security protection capabilities and business continuity.
Patent Information
- Application Number
- CN202610517562.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-04-17
- Publication Date
- 2026-08-25
AI Technical Summary
In existing technologies, it is difficult to prevent the loss of computing power in intelligent computing cloud platforms, and there is a lack of effective protection methods. In particular, it is difficult to identify highly concealed computing power intrusion behaviors when facing malicious attacks, which leads to accelerated hardware aging, soaring power costs and deterioration of business performance.
Collect historical computing power data, identify core detection features and hidden attack features, perform known anomaly detection, full attack chain detection and multi-tenant scenario anomaly detection through multi-engine detection, trace the entire attack path, and perform computing power loss prevention processing based on the entire attack path.
It achieves high-precision, low-false-report protection of computing power for intelligent computing cloud platforms, can automatically reconstruct attack paths, accurately locate intrusion points, reduce false-report rates, improve security capabilities and business assurance levels, and form a self-evolving closed-loop security defense system.
Smart Images

Figure CN122640159A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of intelligent computing centers, smart computing centers, computing power infrastructure, and smart computing cloud technology, specifically to a method and device for preventing computing power loss on an intelligent computing cloud platform. Background Technology
[0002] With the rapid development of artificial intelligence technology, "intelligent computing centers" and "smart computing centers" have emerged.
[0003] An "intelligent computing center" refers to a facility that provides the necessary computing power, data, and algorithms for artificial intelligence applications (such as the development, training, and inference of deep learning models) by utilizing large-scale heterogeneous computing resources, including general-purpose and intelligent computing power. Intelligent computing centers encompass facilities, hardware, and software, and can provide full-stack capabilities from underlying computing power to top-level application enablement.
[0004] "Intelligent computing center" includes, but is not limited to, "intelligent computing center".
[0005] "Intelligent computing center" or artificial intelligence computing center is a type of computing infrastructure that provides computing power services, data services, and algorithm services required for artificial intelligence applications, based on artificial intelligence theory and adopting artificial intelligence computing architecture.
[0006] "Computing power" is the core of "intelligent computing center" and "smart computing center". It is the ability of computer equipment or computing / data center to process parameters. It is the ability of computer hardware and software to work together to execute a certain computing requirement. It is the computing power to achieve the target result output by processing parameter data. It is a new type of productivity that integrates parameter computing power, network carrying capacity and data storage capacity. It mainly provides services to society through computing power infrastructure.
[0007] However, in recent years, malicious attacks targeting the computing resources of intelligent computing cloud platforms have seen explosive growth, particularly in the form of cryptocurrency mining viruses, ransomware, and APT (Advanced Persistent Threat) attacks, forming a highly organized and automated black market industry chain. Attackers exploit unpatched vulnerabilities, weak passwords, and configuration flaws to implant highly concealed and frequently mutated malware, stealing CPU / GPU computing resources for long-term purposes such as cryptocurrency mining, distributed cracking, or botnet construction. These attacks not only cause accelerated hardware aging, soaring electricity costs, and degraded business performance, but are also often accompanied by secondary risks such as lateral movement, data theft, and persistent persistence, seriously threatening the overall security of intelligent computing cloud platforms. Current mainstream security protection systems face severe challenges in dealing with the problem of computing power loss: on the one hand, traditional signature-based detection mechanisms are difficult to identify new covert attacks such as fileless execution, memory residency, and low-frequency calls; on the other hand, intelligent computing cloud platforms themselves have complex architectural characteristics such as heterogeneous distribution, multi-tenant isolation, and dynamic elastic scheduling, which leads to the interweaving of north-south and east-west traffic, the blurring of the boundary between legitimate and malicious computing power behavior, and the inability of single node or single point alarms to effectively capture computing power anomalies across containers, hosts, and tenants.
[0008] It is evident that since the emergence of intelligent computing centers, attacks against intelligent computing cloud platforms have been covert, and preventing the loss of computing power has been difficult. The lack of effective methods to prevent the loss of computing power has been a pressing problem to be solved in this field. Summary of the Invention
[0009] This invention provides a method and apparatus for preventing the loss of computing power in an intelligent computing cloud platform, in order to solve the problems of covert attacks against intelligent computing cloud platforms, high difficulty in preventing the loss of computing power, and lack of effective methods for preventing the loss of computing power in the prior art.
[0010] To solve the above problems, the present invention is implemented as follows: In a first aspect, the present invention provides a method for preventing the loss of computing power in an intelligent computing cloud platform, comprising: Step S1: Collect historical computing power data of the intelligent computing cloud platform, and determine the core detection features and hidden attack features of the intelligent computing cloud platform based on the historical computing power data, as detection reference features; Step S2: The first detection engine performs known anomaly detection on the real-time computing power data of the intelligent computing cloud platform based on the detection reference features to obtain a first detection result; the second detection engine performs full attack chain malicious behavior detection on the real-time computing power data based on the detection reference features to obtain a second detection result; and the third detection engine performs intelligent computing cloud platform computing power scheduling and multi-tenant scenario abnormal behavior detection on the real-time computing power data based on the detection reference features to obtain a third detection result. Step S3: Based on the first detection result, the second detection result, and the third detection result, perform attack tracing to reconstruct the entire attack path; Step S4: Perform computing power loss prevention processing on the intelligent computing cloud platform according to the entire attack path.
[0011] In one embodiment, step S4 includes: Step S4.1: Determine the anomaly level of the entire attack path; Step S4.2: Based on the anomaly level, determine the target attack response strategy corresponding to the entire attack path from the candidate attack response strategies; Step S4.3: Based on the response operation sequence included in the target attack response strategy, perform computing power loss prevention processing on the intelligent computing cloud platform.
[0012] In one embodiment, step S3 includes: Step S3.1: Based on the first detection result, the second detection result, and the third detection result, construct the target attack knowledge graph of the real-time computing power data; Step S3.2: Perform time-series alignment and feature alignment based on the target attack knowledge graph and the historical attack knowledge graph of the intelligent computing cloud platform to determine candidate samples that match the target attack knowledge graph from the historical attack knowledge graph; Step S3.3: Generate the full attack path based on the candidate samples and the target attack knowledge graph.
[0013] In one embodiment, step S3.1 includes: Step S3.1.1: Based on the first detection result, the second detection result, and the third detection result, determine the attack target characteristics, attack timing characteristics, attacked target characteristics, and attack type characteristics of the real-time computing power data; Step S3.1.2: Based on the attack target characteristics, the attack timing characteristics, the attacked target characteristics, and the attack type characteristics, construct the target attack knowledge graph of the real-time computing power data.
[0014] In one embodiment, step S3.2 includes: Step S3.2.1: For any candidate sample in the historical attack knowledge graph, perform temporal alignment based on the attack time sequence features of the candidate sample and the attack time sequence features of the target attack knowledge graph, and perform feature alignment based on the attack object features, attacked object features, and attack type features of the candidate sample and the attack object features, attacked object features, and attack type features of the target attack knowledge graph, respectively. Step S3.2.2: Determine candidate samples that match the target attack knowledge graph based on the temporal alignment results and feature alignment results.
[0015] In one embodiment, step S3.2.1 includes: Step S3.2.1.1: According to the preset matching rules, match the attack object features of the candidate sample with the attack object features of the target attack knowledge graph to generate a first matching result; match the attacked object features of the candidate sample with the attacked object features of the target attack knowledge graph to generate a second matching result; and match the attack type features of the candidate sample with the attack type features of the target attack knowledge graph to generate a third matching result. Step S3.2.1.2: Generate the feature alignment result based on the first matching result, the second matching result, and the third matching result.
[0016] In one embodiment, step S1 includes: Step S1.1: Extract features from the historical computing power data to obtain candidate features; Step S1.2: Perform clustering processing on the candidate features to generate at least one cluster, and perform semantic analysis on the cluster to generate semantic features corresponding to the cluster; Step S1.3: Match the semantic features with the existing attack features of the intelligent computing cloud platform, and filter out the semantic features that do not match successfully to obtain the hidden attack features.
[0017] In one embodiment, step S1.3 includes: The unmatched semantic features are filtered based on a preset whitelist to obtain the hidden attack features.
[0018] Secondly, the present invention also provides a computing power anti-loss device for an intelligent computing cloud platform, comprising: The data acquisition module is used to collect historical computing power data of the intelligent computing cloud platform, and determine the core detection features and hidden attack features of the intelligent computing cloud platform based on the historical computing power data, as detection reference features; The detection module is used to perform known anomaly detection on the real-time computing power data of the intelligent computing cloud platform based on the detection reference features using a first detection engine to obtain a first detection result; to perform full attack chain malicious behavior detection on the real-time computing power data based on the detection reference features using a second detection engine to obtain a second detection result; and to perform intelligent computing cloud platform computing power scheduling and multi-tenant scenario abnormal behavior detection on the real-time computing power data based on the detection reference features using a third detection engine to obtain a third detection result. The source tracing module is used to trace the attack source based on the first detection result, the second detection result, and the third detection result to reconstruct the entire attack path; The processing module is used to perform computing power loss prevention processing on the intelligent computing cloud platform according to the entire attack path.
[0019] Thirdly, the present invention also provides an electronic device, including a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the steps of the computing power anti-loss method of the intelligent computing cloud platform as described in the first aspect above.
[0020] Fourthly, the present invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the computing power loss prevention method for the intelligent computing cloud platform described in the first aspect above.
[0021] Fifthly, the present invention also provides a computer program product, including computer instructions, which, when executed by a processor, implement the steps in the computing power loss prevention method of the intelligent computing cloud platform as described in the first aspect above.
[0022] In this invention, step S1 involves collecting historical computing power data from an intelligent computing cloud platform, and determining the core detection features and hidden attack features of the intelligent computing cloud platform based on the historical computing power data, which serve as detection reference features; step S2 involves using a first detection engine to perform known anomaly detection on the real-time computing power data of the intelligent computing cloud platform according to the detection reference features, obtaining a first detection result; using a second detection engine to perform full attack chain malicious behavior detection on the real-time computing power data according to the detection reference features, obtaining a second detection result; and using a third detection engine to perform intelligent computing cloud platform computing power scheduling and multi-tenant scenario abnormal behavior detection on the real-time computing power data according to the detection reference features, obtaining a third detection result; step S3 involves attack tracing based on the first detection result, the second detection result, and the third detection result to reconstruct the entire attack path; and step S4 involves performing computing power loss prevention processing on the intelligent computing cloud platform according to the entire attack path. In this way, this solution effectively addresses the security challenges faced by intelligent computing cloud platforms in the face of highly complex traffic and increasingly covert attacks, significantly improving overall security capabilities and business assurance levels. On the one hand, based on historical data, it accurately distinguishes between normal high load and malicious computing power intrusion, organically combining core detection features with hidden attack features. This allows the first to third detection engines to cover known anomalies, the entire attack chain, cloud-native scheduling anomalies, and unknown variant attacks, achieving a leap from single-point alerts to multi-dimensional correlations, greatly reducing false alarm rates and improving the detection capabilities for 0-day and advanced persistent anomalies. On the other hand, by deeply integrating contextual information such as attack sequence, victim assets, and attack methods, it automatically reconstructs the complete attack path, accurately locates the initial intrusion point and lateral movement trajectory, completely eliminating the inefficiency and lag in judgment caused by traditional fragmented alerts. This drives automated and hierarchical computing power loss prevention and handling. Ultimately, the system forms a self-evolving closed loop of "detection—source tracing—handling—feedback," continuously transforming newly discovered hidden attack features into detection rules, and promoting the continuous upgrading of the security capabilities of intelligent computing cloud platforms with attack and defense confrontations. Attached Figure Description
[0023] To more clearly illustrate the technical solution of the present invention, the accompanying drawings used in the description of the present invention will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0024] Figure 1 This is a flowchart of a method for preventing the loss of computing power in an intelligent computing cloud platform provided by the present invention; Figure 2 This is a flowchart of another method for preventing the loss of computing power in an intelligent computing cloud platform provided by the present invention; Figure 3 This is a flowchart of another method for preventing the loss of computing power in an intelligent computing cloud platform provided by the present invention; Figure 4 This is a flowchart of another method for preventing the loss of computing power in an intelligent computing cloud platform provided by the present invention; Figure 5 This is a structural diagram of a computing power anti-loss device for an intelligent computing cloud platform provided by the present invention; Figure 6 This is a structural diagram of an electronic device provided by the present invention. Detailed Implementation
[0025] The technical solutions of this invention will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0026] The “computing power” mentioned in this invention refers to: the ability of computer equipment or computing / data center to process information; the ability of computer hardware and software to work together to perform a certain computing requirement; the computing power to achieve the target result output by processing information data; and a new type of productivity that integrates information computing power, network carrying capacity, and data storage capacity, mainly providing services to society through computing power infrastructure.
[0027] The "computational power" (CP) described in this invention refers to the ability of a data center server to process data and output results. It is a comprehensive indicator of a data center's computing power, encompassing general computing power, supercomputing power, and intelligent computing power. The commonly used unit of measurement is floating-point operations per second (FLOPS, 1 EFLOPS = 10^18 FLOPS), with higher values indicating stronger overall computing power. It is estimated that 1 EFLOPS is approximately the computing power output of 5 Tianhe-2A supercomputers, 500,000 mainstream server CPUs, or 2 million mainstream laptops. The calculation formula is: CP = CP 通用 +CP 智能 +CP 超级 .
[0028] The "Network Power" (NP) mentioned in this invention refers to the performance of data transmission capability of computing facilities, which includes comprehensive capabilities such as network architecture, network bandwidth, transmission latency, intelligent management and scheduling, and involves network transmission within and between data centers. It is a comprehensive indicator for measuring network transmission scheduling capability.
[0029] The "Storage Power" (SP) described in this invention refers to the comprehensive capabilities of a data center in four aspects: data storage capacity, performance, security and reliability, and green and low-carbon operation. It is a comprehensive indicator for measuring the data storage capacity of a data center, including external storage devices such as storage arrays and internal storage devices within servers. The commonly used unit of measurement for storage capacity is exabytes (EB, 1EB = 2^60 bytes), while the commonly used unit of measurement for performance is the number of read / write operations per second (IOPS / TB). Disaster recovery ratio is an important indicator of security and reliability.
[0030] The "computing infrastructure" mentioned in this invention refers to a new type of information infrastructure that integrates information computing power, network carrying capacity, and data storage capacity, enabling centralized computing, storage, transmission, and application of information.
[0031] The "new information infrastructure" mentioned in this invention refers to network infrastructure such as 5G networks, fiber optic broadband networks, backbone networks, international communication networks, and satellite internet; computing infrastructure such as data centers, general computing centers, intelligent computing centers, and supercomputing centers; and new technology facilities such as artificial intelligence, blockchain, and quantum computing.
[0032] The “computing power” mentioned in this invention includes: general computing power, intelligent computing power, and supercomputing power.
[0033] The "general computing power" mentioned in this invention refers to the computing power provided by servers based on CPU (Central Processing Unit) chips, which is used to support basic general computing such as cloud computing and edge computing.
[0034] The "intelligent computing power" mentioned in this invention refers to: a computing platform deployed on a large scale based on dedicated chips such as GPU (Graphics Processing Unit), FPGA (Field Programmable Gate Array), and ASIC (Application Specific Integrated Circuit) for various artificial intelligence innovative applications, such as natural language processing and machine vision.
[0035] The “supercomputing power” mentioned in this invention refers to the computing power provided by high-performance computing clusters such as supercomputers. It utilizes the centralized computing resources of multiple computer systems working in parallel and uses a dedicated operating system to handle extremely complex or data-intensive problems. It is mainly used for computing in cutting-edge scientific fields, such as planetary simulation, drug molecule design, and gene analysis.
[0036] The "intelligent computing center" described in this invention refers to a facility that, through the use of large-scale heterogeneous computing resources, including general-purpose computing power (CPU) and intelligent computing power (GPU, FPGA, ASIC, etc.), primarily provides the necessary computing power, data, and algorithms for artificial intelligence applications (such as the development, training, and inference of deep learning models). The intelligent computing center encompasses facilities, hardware, and software, and can provide full-stack capabilities from underlying computing power to top-level application enablement.
[0037] The "intelligent computing cloud platform" mentioned in this invention, abbreviated as "intelligent computing cloud", refers to a cloud computing platform that integrates hardware and software resources based on an intelligent computing center.
[0038] The "intelligent computing center" mentioned in this invention includes, but is not limited to, "smart computing center".
[0039] The "intelligent computing center" mentioned in this invention, also known as an artificial intelligence computing center, is a type of computing infrastructure that provides computing power services, data services, and algorithm services required for artificial intelligence applications, based on artificial intelligence theory and adopting an artificial intelligence computing architecture.
[0040] The "computing center" mentioned in this invention refers to a facility that is mainly composed of infrastructure such as wind, thermal, hydro, and electricity, and IT hardware and software equipment, and has computing power, carrying capacity, and storage capacity, including general data centers, intelligent computing centers, supercomputing centers, etc.
[0041] The "supercomputing center" mentioned in this invention refers to a supercomputing data center, which is a data center based on supercomputers or large-scale computing clusters. It can provide large-scale computing, storage and network services and is widely used in aerospace, defense, oil exploration, climate modeling and genome sequencing and other application scenarios.
[0042] The “computing resources” mentioned in this invention refer to the technologies and facilities required for the development of the digital society that have the ability to compute, transmit, store and apply information, including but not limited to computing resources such as CPUs and GPUs, network resources such as switches and routers, storage resources such as storage arrays and distributed storage, security resources such as firewalls and intrusion detection systems, and supporting and guaranteeing resources such as wind, fire, water and electricity.
[0043] The "model" mentioned in this invention includes, but is not limited to, "large language model" and "multimodal large model".
[0044] The "large language model" mentioned in this invention refers to a large-scale language model (LLM), which is a language model with a large number of parameters. It is designed to understand and generate human language, and is trained with a large amount of text data. It can perform a wide range of tasks, including text summarization, translation, and sentiment analysis.
[0045] The “Multimodal Large Models” mentioned in this invention refer to models that combine multimodal information such as text, images, videos, and audio for training, including but not limited to multimodal large language models.
[0046] It is important to emphasize that preventing the loss of computing power in the intelligent computing cloud platform of this invention is far more difficult than preventing the loss of network data in existing technologies. The following is a detailed technical analysis of why preventing the loss of computing power in the intelligent computing cloud platform of this invention is far more difficult than preventing the loss of network data in existing technologies: 1. The objects of protection are fundamentally different.
[0047] The core protection objective of intelligent computing cloud platforms is to prevent the illegal occupation of computing resources (CPU / GPU / memory / power), while network data security protection safeguards the confidentiality, integrity, and availability of data.
[0048] Computing power hijacking often manifests as "high load on legitimate processes" without obvious malicious traffic characteristics. Compared to abnormal traffic, it is more covert and not easy to detect.
[0049] 2. The attack is more covert.
[0050] Traditional cyberattacks are often accompanied by high-noise characteristics such as port scanning and known malicious payloads, which can be effectively intercepted through signature verification, blacklists / whitelists, and protocol anomaly detection.
[0051] However, computational attacks (such as advanced mining viruses) involve fileless execution: the code resides in memory, leaves no disk trace, and can intelligently adjust speed; for example, a computational attack can dynamically adjust CPU usage (e.g., using only 30%) to avoid triggering threshold alarms. Furthermore, computational attacks can disguise themselves as legitimate processes, for example, by changing their names to mimic system processes.
[0052] 3. More complex detection dimensions: requires cross-layer fusion perception.
[0053] To prevent computing power loss, full-stack coverage is required, which includes hardware, operating system (OS), containers, applications, and business logic.
[0054] Traditional cyberattacks typically only require detection at the network layer and some application layers, and the deployment scope is far smaller than that needed for computing power loss prevention.
[0055] 4. The complex and highly volatile architecture of intelligent computing cloud platforms increases the difficulty of detection.
[0056] The intelligent computing cloud platform has the following characteristics, which greatly increase the difficulty of preventing the loss of its computing power: Dynamic and elastic scheduling, intelligent computing cloud platform containers start and stop in seconds, and virtual machines automatically expand and shrink, resulting in drastic fluctuations in legitimate computing power, making it difficult to establish a stable baseline.
[0057] In a multi-tenant resource-sharing environment, malicious tenants can exploit the "neighbor effect" to steal shared CPU caches and launch side-channel attacks to pollute cross-tenant computing power.
[0058] In heterogeneous computing power pools and intelligent computing cloud platforms with mixed scheduling of CPU / GPU / FPGA, attacks can specifically target high-value GPU nodes, which traditional CPU monitoring cannot cover.
[0059] Computing power is the core productive force of the digital economy, and intelligent computing cloud platforms, as the core carriers of centralized computing power, have computing power security that directly affects business operations, asset security, industry development, and even the overall security of computing power infrastructure. Furthermore, the increasing industrialization and scaling up of computing power attacks makes preventing computing power loss an urgent need. Intelligent computing cloud platforms are platforms that centralize computing power and scale tenants. The loss of computing power in a single node can quickly spread to the entire cluster, even affecting the computing power usage of multiple tenants and triggering a chain reaction. At the same time, intelligent computing cloud platforms carry a large amount of core government and enterprise data and business. Computing power attacks are often not just about resource encroachment, but may also be accompanied by secondary anomalies such as data theft and system tampering. Behind the loss of computing power is the breach of the overall security defense of the intelligent computing cloud platform, which further exacerbates the risks to data security and business security.
[0060] Therefore, preventing computing power loss in intelligent computing cloud platforms is not only a "security issue," but also a systemic challenge integrating resource scheduling, performance engineering, behavioral modeling, and proactive defense. It requires security capabilities to be deeply embedded in the kernel of the intelligent computing cloud platform, achieving a leap from "seeing traffic" to "understanding the intent of computing power." This invention precisely solves this pressing problem in the field of computing power.
[0061] Therefore, its technical difficulty, engineering complexity, and protection cost are significantly higher than those of traditional network data routing security protection.
[0062] Please see Figure 1 , Figure 1 This is a flowchart of a method for preventing computing power loss in an intelligent computing cloud platform provided by the present invention, as shown below. Figure 1 As shown, the method includes: Step S1: Collect historical computing power data of the intelligent computing cloud platform, and determine the core detection features and hidden attack features of the intelligent computing cloud platform based on the historical computing power data, as detection reference features.
[0063] Intelligent computing cloud platforms typically integrate heterogeneous hardware (CPU / GPU / FPGA) and multi-tenant scheduling, resulting in computing power utilization characteristics as shown in the table below:
[0064] This leads to a high degree of overlap between the "normal fluctuations" of legitimate business operations and the "covert encroachment" of malicious attacks, making features based on static thresholds or simple statistics highly ineffective. Furthermore, with advancements in attack methods, more and more covert and unprecedented attack techniques will emerge, further increasing the difficulty of preventing the loss of computing power.
[0065] In intelligent computing cloud platforms, identifying core detection features and hidden attack characteristics based on historical computing power data is a crucial prerequisite for building a high-precision, low-false-positive, and adaptive computing power security protection system. Due to the heterogeneity, dynamism, multi-tenant sharing, and highly fluctuating business load of intelligent computing cloud platforms, directly using raw indicators can easily lead to a large number of false positives or false negatives. Therefore, it is essential to extract truly security-discriminating "detection reference features" from massive amounts of historical computing power data through systematic, multi-dimensional, and context-aware feature engineering methods.
[0066] It should be noted that the core detection features refer to features that have been clearly defined, modeled and used for alerting or blocking in the existing security detection system. They usually come from known attack patterns (such as TTPs in MITRE ATT&CK), historical event reviews, anomaly intelligence or manual rules.
[0067] Hidden attack signatures refer to the potential discriminative characteristics of new or variant attack behaviors that are not yet covered by the current detection system, have not appeared in historical alerts or rule bases, but exist in massive amounts of data. Hidden attack signatures mean that the attack has already occurred, but we have not yet identified its pattern.
[0068] The core features of detection can be determined based on prior knowledge, such as features summarized by security experts based on known attacks.
[0069] Hidden attack features do not rely on prior knowledge, but rather search for "dissimilar" patterns from massive amounts of historical data. In this embodiment of the invention, hidden attack features can be determined through the following method: Unsupervised anomaly detection (Isolation Forest, AutoEncoder); Behavioral clustering (DBSCAN, Gaussian Mixture) discovers sparse clusters; PrefixSpan mining discovers unrecorded attack chains; GraphSAGE (GNN) identifies hidden control relationships.
[0070] The technical effect of step S1: Collecting historical computing power data and using it to determine core detection features and hidden attack features as detection reference features. The technical effect is not an abstract concept, but a quantifiable, perceptible, and verifiable leap in security capabilities. At the same time, it builds a closed-loop mechanism that automatically discovers hidden attack features from massive amounts of data and efficiently transforms them into core detection features, achieving the proactive advantage of "being locked down when the attacker thinks they are invisible", and providing a data foundation for subsequent computing power loss prevention detection.
[0071] Step S2: The first detection engine performs known anomaly detection on the real-time computing power data of the intelligent computing cloud platform based on the detection reference features to obtain the first detection result; the second detection engine performs full attack chain malicious behavior detection on the real-time computing power data based on the detection reference features to obtain the second detection result; and the third detection engine performs intelligent computing cloud platform computing power scheduling and multi-tenant scenario abnormal behavior detection on the real-time computing power data based on the detection reference features to obtain the third detection result.
[0072] Traditional security detection systems (such as static threshold alerts and single-point detection) are showing signs of fatigue in addressing the two core pain points of complex traffic and the stealth of new attacks on intelligent computing cloud platforms. Traffic complexity is reflected in the high proportion of east-west microservice communication, the proliferation of encrypted traffic, and the high degree of intertwining between legitimate business and malicious behavior; Attack stealth: Techniques such as fileless execution, low-frequency heartbeat attacks, memory residency, and the use of legitimate toolchains allow attacks to "hide" within normal traffic.
[0073] Therefore, it is necessary to break through the limitations of traditional single detection and build a precise detection system that covers the entire chain of "data collection - feature extraction - multi-dimensional detection - intelligent judgment - automatic response".
[0074] To address the aforementioned problems, this invention proposes a scheme for parallel detection based on three different detection methods. It should be noted that the three detection methods in this embodiment are shown in the table below:
[0075] It should be noted that the first engine, the second engine, and the third engine can be the integrated terminal rule engine, the anomaly detector engine, and the cloud scenario-specific behavior analysis engine, respectively.
[0076] The technical effect of step S2: Through three parallel / cascaded detection methods, in-depth analysis of the real-time computing power data of the intelligent computing cloud platform is performed from different perspectives. This design fully considers the complexity of the cloud environment, the diversity of attacks, and the depth of defense. The following is a systematic expansion of this architecture, including the design goals, technical implementation, complementary relationships, and overall synergistic value of each engine.
[0077] Step S3: Based on the first detection result, the second detection result, and the third detection result, perform attack tracing to reconstruct the entire attack path.
[0078] In existing technologies, when abnormal computing power usage is detected, multiple independent alarms are typically issued, such as "Host A CPU abnormal" or "Host B has suspicious external connections." This fragmented alarm system leads to a significant increase in the number of alarms, easily causing alarm fatigue. It also greatly increases the processing and judgment costs of alarms, and increases response latency.
[0079] This invention traces the attack source based on the first, second, and third detection results to reconstruct the entire attack path. It abandons the isolated and fragmented single-point alarms in traditional security systems, and instead deeply correlates multiple dimensions such as attack sequence, victim assets, and attack methods. This not only accurately locates the source and scope of the attack, but also drives automated response and risk quantification decision-making.
[0080] In this embodiment of the invention, attack tracing is performed based on the first, second, and third detection results. This can be achieved by processing the first, second, and third detection results to generate a unified structured event. Then, multi-dimensional correlation analysis is performed based on this structured event to reconstruct the entire attack path. For example, correlation analysis can be performed from four dimensions: temporal correlation, asset correlation, method correlation, and behavioral context correlation, to reconstruct the entire attack path.
[0081] Another possible approach is to automatically construct the entire attack path by building an attack graph. This can be achieved by modeling using a graph database (such as Neo4j) or a property graph, and then using a graph traversal algorithm to trace back from any alert node to the initial intrusion point to reconstruct the entire attack path.
[0082] The technical effect of step S3: Attack tracing based on multi-engine detection results and reconstructing the entire attack path is a key leap for modern cloud-native security systems from "passive response" to "active immunity". It abandons the isolated and fragmented single-point alarms in traditional security systems, and instead deeply correlates multiple dimensions such as attack sequence, victim assets, and attack methods. This not only accurately locates the source of the attack and the scope of its impact, but also drives automated response and risk quantification decision-making.
[0083] Step S4: Perform computing power loss prevention processing on the intelligent computing cloud platform according to the entire attack path.
[0084] Existing methods for preventing computing power loss typically involve blocking attack behaviors, but attackers often recover quickly through multi-point implantation, container escape, scheduler hijacking, and other methods. To address these issues, the computing power loss prevention method in this invention implements one or more of the following:
[0085] In this embodiment of the invention, corresponding anti-loss measures can also be determined based on the type, level, and other attributes of the entire attack path.
[0086] The technical effect of step S4: The method of the present invention no longer passively cleans up the stolen computing power, but implements a precise, efficient and adaptive computing power protection strategy based on a complete understanding of the attack entry point, propagation path, persistence means and scope of impact.
[0087] In this invention, step S1 involves collecting historical computing power data of the intelligent computing cloud platform and determining the core detection features and hidden attack features of the intelligent computing cloud platform based on the historical computing power data, which serve as detection reference features; step S2 involves using a first detection engine to perform known anomaly detection on the real-time computing power data of the intelligent computing cloud platform based on the detection reference features, obtaining a first detection result; using a second detection engine to perform full attack chain malicious behavior detection on the real-time computing power data based on the detection reference features, obtaining a second detection result; and using a third detection engine to perform intelligent computing cloud platform computing power scheduling and multi-tenant scenario abnormal behavior detection on the real-time computing power data based on the detection reference features, obtaining a third detection result; step S3 involves attack tracing based on the first, second, and third detection results to reconstruct the entire attack path; and step S4 involves performing computing power loss prevention processing on the intelligent computing cloud platform based on the entire attack path. In this way, this solution effectively solves the security protection challenges of intelligent computing cloud platforms in the face of highly complex traffic and increasingly covert attacks, significantly improving overall security capabilities and business assurance levels. On the one hand, based on historical data, it accurately distinguishes between normal high load and malicious computing power intrusion, organically combining core detection features with hidden attack features. This allows the first to third detection engines to cover known anomalies, the entire attack chain, cloud-native scheduling anomalies, and unknown variant attacks, respectively. This achieves a leap from single-point alerts to multi-dimensional correlation, significantly reducing false alarm rates and improving the detection capabilities for 0-day and advanced persistent anomalies. On the other hand, by deeply integrating contextual information such as attack sequence, victim assets, and attack methods, it automatically reconstructs the complete attack path, accurately locates the initial intrusion point and lateral movement trajectory, and completely eliminates the inefficiency and lag in judgment caused by traditional fragmented alerts. This drives automated and hierarchical computing power loss prevention and handling. Ultimately, the system forms a self-evolving closed loop of "detection—source tracing—handling—feedback," continuously transforming newly discovered hidden attack features into detection rules and promoting the continuous upgrading of platform security capabilities with attack and defense confrontations.
[0088] In one embodiment, such as Figure 2 As shown, step S4 includes: Step S4.1: Determine the anomaly level of the entire attack path.
[0089] In this embodiment of the invention, the entire attack path can be comprehensively evaluated from multiple dimensions to determine the anomaly level of the entire attack path. For example, a multi-dimensional evaluation can be performed using the dimensions described in the table below:
[0090] In another possible approach, the entire attack path can be scored using a quantification model, such as a weighted scoring model.
[0091] The technical effect of step S4.1: Determining the anomaly level of the entire attack path transforms complex offensive and defensive confrontations into quantifiable, decision-making, and actionable risk signals.
[0092] Step S4.2: Based on the anomaly level, determine the target attack response strategy corresponding to the entire attack path from the candidate attack response strategies.
[0093] In this embodiment of the invention, the intelligent computing cloud platform pre-configures a layered, modular, and programmable attack response strategy library, with each strategy containing a set of ordered response operations.
[0094] It should be noted that as attack methods advance, more and more covert and previously unseen attack methods will emerge. Therefore, the strategy library in this embodiment of the invention supports online updates: when a new attack mode is confirmed, strategies can be quickly added or adjusted.
[0095] Meanwhile, the policy library in this embodiment of the invention supports tenant-defined policies: highly sensitive customers such as those in finance and scientific research can apply for stricter default response levels.
[0096] The technical effect of step S4.2: To achieve "different handling for different risks," balancing security and business continuity. Step S4.3: Based on the response operation sequence included in the target attack response strategy, perform computing power loss prevention processing on the intelligent computing cloud platform.
[0097] In this invention, step S4.1 involves determining the anomaly level of the entire attack path; step S4.2 involves determining the target attack response strategy corresponding to the entire attack path from candidate attack response strategies based on the anomaly level; and step S4.3 involves performing computing power loss prevention processing on the intelligent computing cloud platform based on the response operation sequence included in the target attack response strategy. Thus, through a three-tiered progressive mechanism of anomaly classification, strategy matching, and precise execution, this invention transforms the abstract "entire attack path" into quantifiable, programmable, and automatically executable computing power protection actions. This not only achieves efficient loss mitigation and eradication of current attacks but also constructs an adaptive security defense system driven by practical application and centered on data closed-loop, providing a solid, reliable, and sustainable security foundation for intelligent computing cloud platforms in the new era of AI computing power intensity, multi-tenant sharing, and highly covert attacks.
[0098] In one embodiment, such as Figure 3 As shown, step S3 includes: Step S3.1: Based on the first detection result, the second detection result, and the third detection result, construct a target attack knowledge graph of real-time computing power data.
[0099] It should be noted that the following steps are used to construct the target attack knowledge graph: Step S3.1.1: Based on the first detection result, the second detection result, and the third detection result, determine the attack target characteristics, attack timing characteristics, attacked target characteristics, and attack type characteristics of the real-time computing power data; It should be noted that this step aims to extract atomic features with security semantics from the three types of detection results, serving as the cornerstone for building the knowledge graph. These features are no longer limited to raw metrics (such as CPU utilization), but rather are higher-order attributes with attack context meaning.
[0100] 1. Characteristics of the target of the attack.
[0101] This can be obtained by parsing the attack source IP, domain name, URL, and other data from the first, second, and third detection results.
[0102] 2. Attack timing characteristics.
[0103] It can be obtained by parsing the event timestamps, attack phase sequence, and phase time intervals of the first, second, and third detection results.
[0104] 3. Characteristics of the target being attacked.
[0105] This can be obtained by parsing data such as the victim asset ID, the tenant / project / namespace, and key asset tags from the first, second, and third detection results.
[0106] 4. Characteristics of attack types.
[0107] The attack categories (such as computing power theft, data leakage, denial of service), sub-types (such as "memory mining", "GPU mining", "container escape"), attack families, and whether they are automated scripts / internal misoperations can be obtained by parsing the first, second, and third detection results.
[0108] The technical effect of step S3.1.1 is to transform the originally scattered and heterogeneous detection signals into a structured and semantic attack relationship network, so that the system can not only "see the anomaly" but also "understand the attack intent".
[0109] Step S3.1.2: Based on the characteristics of the attack target, the attack time sequence, the characteristics of the attacked target, and the attack type, construct a target attack knowledge graph of real-time computing power data.
[0110] Based on the four types of features mentioned above, the system constructs a dynamic property graph centered on attack events. Its nodes and edges carry rich semantics, supporting efficient querying and reasoning. It also enables full attack path visualization, automatically generating interactive attack chain graphs and supporting drill-down to every step of the detail. This provides a data foundation for subsequent attribution and attack analysis.
[0111] The technical effect of step S3.1.2: By constructing a target attack knowledge graph, the original security data can be upgraded into a computable, reasonable, and actionable attack cognitive model.
[0112] Step S3.2: Perform temporal alignment and feature alignment between the target attack knowledge graph and the historical attack knowledge graph of the intelligent computing cloud platform to determine candidate samples that match the target attack knowledge graph from the historical attack knowledge graph.
[0113] It should be noted that candidate samples do not refer to observation segments in historical data that belong to the same attack path (i.e., the same round of attack activity) or on different tenants / nodes as the current real-time computing power data.
[0114] Data from the entire attack path is a record of a series of attack behaviors initiated by the same attacker, using the same toolchain, following consistent tactical logic, and acting on related assets within a continuous time window.
[0115] By aligning the real-time constructed target attack knowledge graph with the platform's accumulated historical attack knowledge graph through temporal and multi-dimensional feature alignment, context-enhanced identification and intelligent matching of the current attack are achieved. This allows for the rapid identification of the most similar known attack patterns (candidate samples) from historical experience, thereby accelerating anomaly assessment, improving detection confidence, and providing prior knowledge support for subsequent response strategies.
[0116] It should be noted that step S3.2 also includes the following steps: Step S3.2.1: For any candidate sample in the historical attack knowledge graph, perform temporal alignment based on the attack temporal features of the candidate sample with the attack temporal features of the target attack knowledge graph, and perform feature alignment based on the attack object features, attacked object features, and attack type features of the candidate sample with the attack object features, attacked object features, and attack type features of the target attack knowledge graph, respectively.
[0117] In intelligent computing cloud platforms, attackers often employ highly automated, templated, and reusable attack methods. The behavior of the same attack family can be highly similar across different times and tenant environments.
[0118] Therefore, if the current attack can be accurately matched with historically successful cases, it is possible to: quickly determine the attack type and intent, reuse verified handling solutions, predict the next move of the attack (such as whether it will move laterally), and improve the ability to generalize the identification of variant attacks.
[0119] In this embodiment of the invention, step S3.2.1.1 involves matching the attack object features of the candidate sample with the attack object features of the target attack knowledge graph according to a preset matching rule to generate a first matching result, matching the attacked object features of the candidate sample with the attacked object features of the target attack knowledge graph to generate a second matching result, and matching the attack type features of the candidate sample with the attack type features of the target attack knowledge graph to generate a third matching result. Step S3.2.1.2 involves generating a feature alignment result based on the first matching result, the second matching result, and the third matching result.
[0120] It should be noted that time alignment is a method for determining whether the current attack and historical attacks are consistent in their behavioral evolution rhythm.
[0121] The attack phase sequence of both attacks (e.g., from initial access to execution to persistence to lateral movement) can be dynamically time-warped (or the longest common subsequence can be matched, allowing time offsets (e.g., historical attacks took 5 minutes, while the current attack takes 6 minutes), but the order of critical phases must be consistent.
[0122] Feature alignment is a triple feature matching process. The three matching results are then merged into a unified feature alignment score, which is combined with the temporal alignment score to form the final candidate sample similarity score.
[0123] In one possible approach, a weighted average or learning-based fusion method can be used to combine the three matching results into a unified feature alignment score.
[0124] In this embodiment of the invention, the triple matching in step S3.2.1.1 ensures semantic consistency across the three dimensions of the attacking subject, the victim, and the nature of the attack, while the fusion scoring in step S3.2.1.2 achieves a leap from "local similarity" to "overall matching".
[0125] Step S3.2.2: Determine candidate samples that match the target attack knowledge graph based on the temporal alignment results and feature alignment results.
[0126] In this embodiment of the invention, step S3.2.2 is a key decision-making step in the intelligent attack assessment process. Its core task is to comprehensively analyze the temporal alignment results and feature alignment results to select candidate samples (Top-K most similar historical attack events) that highly match the current target attack from the massive historical attack knowledge graph. This step not only determines the accuracy of subsequent source tracing and response but also directly affects the generalization capability and automation level of the security system.
[0127] It should be noted that not all historical samples with high alignment scores should be considered valid matches. Step S3.2.2 can also set multi-level judgment conditions to ensure that candidate samples have both semantic consistency and behavioral comparability. For example, a comprehensive similarity threshold can be set (to filter weakly related samples and avoid noise interference), key feature forced matching (to ensure that the attack is essentially the same and prevent "similar in form but different in essence"), and temporal structure consistency (to exclude interference items that are only similar in some stages) to limit step S3.2.2.
[0128] Step S3.3: Generate the full attack path based on candidate samples and the target attack knowledge graph.
[0129] In this embodiment of the invention, generating the full attack path based on candidate samples and the target attack knowledge graph is the core step in realizing the leap from "fragmented alerts" to "complete attack narratives". This step is not a simple data splicing, but rather a fusion of current real-time observations (target attack knowledge graph) and historical related fragments (candidate samples) through spatiotemporal alignment, causal reasoning, and context enhancement, to reconstruct the complete evolution chain of this attack event from the initial entry point to the current state.
[0130] One possible implementation involves the following steps: Step 1: Perform spatiotemporal anchor point alignment, including temporal alignment and spatial alignment.
[0131] Time alignment: Using the earliest attack behavior as t0, the time offset of all events is unified.
[0132] Spatial alignment: Establish cross-node / tenant connections through shared attributes, such as the same domain name / wallet address, the same malicious payload hash or command line fingerprint, the same permission context, etc.
[0133] Step 2: Causal chain deduction. Rule engines or lightweight graph neural networks (GNNs) can be used to determine the dependencies and driving relationships between events.
[0134] Step 3: Intelligent completion of missing links. If logical breakpoints exist in the path (e.g., no "persistence" but the attack lasts for several hours), the most likely intermediate stage is inserted based on the attack common sense base: The basis for supplementing information includes: historical behavior of attacks originating from the same source, common persistence techniques of the platform, and weaknesses in the current environment configuration.
[0135] The technical effect of step S3.3: In the intelligent computing cloud platform, this full-path generation mechanism, which is centered on a single attack instance, integrates real-time and historical fragments, and has both restoration and prediction capabilities, is the cornerstone for achieving computing power that is loss-proof, reliable, secure, and explainable. It marks a key leap in the security system from "passive detection" to "proactive cognition and precise countermeasures".
[0136] In one embodiment, such as Figure 4 As shown, step S1 includes: Step S1.1: Extract features from historical computing power data to obtain candidate features.
[0137] Step S1.2: Perform clustering processing on the candidate features to generate at least one cluster, and perform semantic analysis on the cluster to generate the semantic features corresponding to the cluster.
[0138] Step S1.3: Match the semantic features with the existing attack features of the intelligent computing cloud platform, and filter out the semantic features that do not match successfully in order to obtain hidden attack features.
[0139] In this embodiment of the invention, semantic features that fail to match can be filtered based on a preset whitelist to obtain hidden attack features.
[0140] It's important to note that the whitelist defines a trusted, legitimate, and permitted list. The system only accepts items from this list; all other content not listed is considered untrustworthy or a potential threat and is automatically blocked or rejected. The whitelist can have multi-dimensional context, such as tenant, role, task type, time window, and resource tags.
[0141] Anomalies outside of known legitimate behavior (whitelist) are not necessarily attacks; however, if all explainable normal behavior can be ruled out, the remaining part is very likely to contain advanced persistent threats (APTs) or covert attacks.
[0142] For each semantic feature that "did not match": If the action matches the whitelist, it is considered a known legitimate action and is discarded. If the whitelist is not matched, it is judged as an inexplicable anomaly and retained as a candidate for hidden attack characteristics.
[0143] In another possible approach, semantic features can be detected using artificial intelligence, and the results of the AI detection can be used to determine whether the semantic features are hidden attack features.
[0144] It should be noted that historical computing power data covers multi-dimensional runtime metrics, including but not limited to: Resource usage metrics, such as CPU utilization, GPU memory / computing power usage, memory bandwidth, I / O throughput, etc.
[0145] Scheduling context, such as Pod creation / destruction events, container images, startup commands, etc.
[0146] Network behavior, such as external IP / domain names, DNS query frequency, connection port distribution, and traffic encryption ratio.
[0147] Process behavior, such as abnormal process trees, sensitive system calls (such as ptrace, mount), binary file hashes, etc.
[0148] In this embodiment of the invention, a multi-granularity, multi-perspective feature extraction method can also be used to generate a candidate feature set. Then, candidate features with similar behavioral patterns are grouped into one category, with each cluster representing a potential behavioral paradigm (which could be normal business or an unknown attack). The semantic features of the clusters are compared with the platform's existing attack feature library. If a match is found, the semantic feature belongs to a known attack and is included in the regular detection process. If no match is found, but one of the following conditions is met, it is determined to be a hidden attack feature: Samples in the clusters corresponding to semantic features exhibit one or more of the following features: high resource anomaly, high network suspicion, and lack of business explanation.
[0149] Or it may appear repeatedly in multiple tenants or at multiple time periods.
[0150] Or it may be similar to known attacks in some dimensions (such as having the same high GPU load), but using new tools, etc.
[0151] In this embodiment of the invention, step S1.1 involves extracting features from historical computing power data to obtain candidate features; step S1.2 involves clustering the candidate features to generate at least one cluster, and performing semantic analysis on the clusters to generate semantic features corresponding to the clusters; step S1.3 involves matching the semantic features with existing attack features of the intelligent computing cloud platform, and filtering out unmatched semantic features to obtain hidden attack features. In this way, by filtering out unmatched semantic features to determine "hidden attack features," the platform can continuously expand its anomaly awareness boundaries, ensuring that even in the face of highly mutated, zero-day exploitation, or internal abuse scenarios, it can still maintain a keen awareness of core risks such as computing power theft and data leakage.
[0152] Please see Figure 5 , Figure 5This is a structural diagram of a computing power anti-loss device for an intelligent computing cloud platform provided by the present invention, as shown below. Figure 5 As shown, the computing power loss prevention device 500 of the intelligent computing cloud platform includes: The acquisition module 501 is used to collect historical computing power data of the intelligent computing cloud platform, and to determine the core detection features and hidden attack features of the intelligent computing cloud platform based on the historical computing power data, which serve as detection reference features.
[0153] The detection module 502 is used to perform known anomaly detection on the real-time computing power data of the intelligent computing cloud platform based on the detection reference features through the first detection engine to obtain a first detection result; to perform full attack chain malicious behavior detection on the real-time computing power data based on the detection reference features through the second detection engine to obtain a second detection result; and to perform intelligent computing cloud platform computing power scheduling and multi-tenant scenario abnormal behavior detection on the real-time computing power data based on the detection reference features through the third detection engine to obtain a third detection result.
[0154] The tracing module 503 is used to trace the attack source based on the first detection result, the second detection result, and the third detection result to reconstruct the entire attack path.
[0155] Processing module 504 is used to perform computing power loss prevention processing on the intelligent computing cloud platform according to the entire attack path.
[0156] In one embodiment, the processing module 504 includes: The determination unit is used to determine the anomaly level of the entire attack path; The strategy unit is used to determine the target attack response strategy corresponding to the entire attack path from the candidate attack response strategies based on the anomaly level. The processing unit is used to perform computing power loss prevention processing on the intelligent computing cloud platform based on the response operation sequence included in the target attack response strategy.
[0157] In one embodiment, the traceability module 503 includes: The building unit is used to construct a target attack knowledge graph of real-time computing power data based on the first detection result, the second detection result, and the third detection result. The alignment unit is used to perform temporal and feature alignment based on the target attack knowledge graph and the historical attack knowledge graph of the intelligent computing cloud platform, so as to determine candidate samples that match the target attack knowledge graph from the historical attack knowledge graph. The generation unit is used to generate the full attack path based on candidate samples and the target attack knowledge graph.
[0158] In one embodiment, the building unit is further configured to: Based on the first detection result, the second detection result, and the third detection result, the attack target characteristics, attack timing characteristics, attacked target characteristics, and attack type characteristics of the real-time computing power data are determined. Based on the characteristics of the attack target, the attack time sequence, the characteristics of the attacked target, and the attack type, a target attack knowledge graph of real-time computing power data is constructed.
[0159] In one embodiment, the alignment unit is also used for: For any candidate sample in the historical attack knowledge graph, the attack time sequence features of the candidate sample are aligned with the attack time sequence features of the target attack knowledge graph. Furthermore, the attack object features, attacked object features, and attack type features of the candidate sample are aligned with the attack object features, attacked object features, and attack type features of the target attack knowledge graph, respectively. Candidate samples matching the target attack knowledge graph are determined based on temporal alignment results and feature alignment results.
[0160] In one embodiment, the alignment unit is also used for: According to the preset matching rules, the attack object features of the candidate sample are matched with the attack object features of the target attack knowledge graph to generate a first matching result; the attacked object features of the candidate sample are matched with the attacked object features of the target attack knowledge graph to generate a second matching result; and the attack type features of the candidate sample are matched with the attack type features of the target attack knowledge graph to generate a third matching result. Feature alignment results are generated based on the first matching result, the second matching result, and the third matching result.
[0161] In one embodiment, the acquisition module 501 includes: The extraction unit is used to extract features from historical computing power data to obtain candidate features.
[0162] Clustering units are used to cluster candidate features to generate at least one cluster, and to perform semantic analysis on the clusters to generate semantic features corresponding to the clusters.
[0163] The matching unit is used to match semantic features with existing attack features on the intelligent computing cloud platform, and to filter out unmatched semantic features in order to obtain hidden attack features.
[0164] In one embodiment, the matching unit is further configured to: Based on a pre-defined whitelist, unmatched semantic features are filtered to obtain hidden attack features.
[0165] The computing power loss prevention device for the intelligent computing cloud platform provided by this invention can realize the various processes of the various embodiments of the above-mentioned intelligent computing cloud platform computing power loss prevention method. The technical features are one-to-one and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0166] It should be noted that the computing power anti-loss device of the intelligent computing cloud platform in this invention can be a device, or it can be a component, integrated circuit, or chip in an electronic device.
[0167] The present invention also provides an electronic device, see [link to relevant documentation]. Figure 6 , Figure 6 This is a schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. The electronic device includes a memory 601, a processor 602, and a program or instructions stored in the memory 601 that run on the processor 602. When the program or instructions are executed by the processor 602, they can achieve the following: Figure 1 The steps in the corresponding intelligent computing cloud platform's method for preventing computing power loss, and the same beneficial effects, will not be elaborated here.
[0168] The processor 602 can be a CPU, ASIC, FPGA or GPU.
[0169] Those skilled in the art will understand that all or part of the steps of the above-described intelligent computing cloud platform computing power loss prevention method embodiment can be implemented by hardware related to program instructions, and the program can be stored in a readable medium.
[0170] The present invention also provides a readable storage medium on which a computer program is stored, and which, when executed by a processor, can perform the above-described functions. Figure 1 Any step in the embodiment of the computing power loss prevention method for the corresponding intelligent computing cloud platform can achieve the same technical effect, and will not be described again here to avoid repetition. The storage medium mentioned includes, for example, read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.
[0171] The present invention also provides a computer program product, including computer instructions that, when executed by a processor, implement the above-described... Figure 1 The various processes of the corresponding intelligent computing cloud platform's computing power loss prevention method embodiment can achieve the same technical effect, and will not be described again here to avoid repetition.
[0172] The terms "first," "second," etc., used in this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to these processes, methods, products, or apparatuses. Additionally, the use of "and / or" in this invention indicates at least one of the connected objects, such as A and / or B and / or C, representing seven possibilities: A alone, B alone, C alone, both A and B present, both B and C present, both A and C present, and A, B, and C present.
[0173] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0174] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, air conditioner, or second terminal device, etc.) to execute the methods of the various embodiments of the present invention.
[0175] The embodiments of the present invention have been described above with reference to the accompanying drawings. However, the present invention is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of the present invention without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of the present invention.
Claims
1. A method for preventing computing power loss in an intelligent computing cloud platform, characterized in that, include: Step S1: Collect historical computing power data of the intelligent computing cloud platform, and determine the core detection features and hidden attack features of the intelligent computing cloud platform based on the historical computing power data, as detection reference features; Step S2: The first detection engine performs known anomaly detection on the real-time computing power data of the intelligent computing cloud platform based on the detection reference features to obtain a first detection result; the second detection engine performs full attack chain malicious behavior detection on the real-time computing power data based on the detection reference features to obtain a second detection result; and the third detection engine performs computing power scheduling and multi-tenant scenario abnormal behavior detection on the real-time computing power data of the intelligent computing cloud platform based on the detection reference features to obtain a third detection result. Step S3: Based on the first detection result, the second detection result, and the third detection result, perform attack tracing to reconstruct the entire attack path; Step S4: Perform computing power loss prevention processing on the intelligent computing cloud platform according to the entire attack path.
2. The method according to claim 1, characterized in that, Step S4 includes: Step S4.1: Determine the anomaly level of the entire attack path; Step S4.2: Based on the anomaly level, determine the target attack response strategy corresponding to the entire attack path from the candidate attack response strategies; Step S4.3: Based on the response operation sequence included in the target attack response strategy, perform computing power loss prevention processing on the intelligent computing cloud platform.
3. The method according to claim 1, characterized in that, Step S3 includes: Step S3.1: Based on the first detection result, the second detection result, and the third detection result, construct the target attack knowledge graph of the real-time computing power data; Step S3.2: Perform time-series alignment and feature alignment based on the target attack knowledge graph and the historical attack knowledge graph of the intelligent computing cloud platform to determine candidate samples that match the target attack knowledge graph from the historical attack knowledge graph; Step S3.3: Generate the full attack path based on the candidate samples and the target attack knowledge graph.
4. The method according to claim 3, characterized in that, Step S3.1 includes: Step S3.1.1: Based on the first detection result, the second detection result, and the third detection result, determine the attack target characteristics, attack timing characteristics, attacked target characteristics, and attack type characteristics of the real-time computing power data; Step S3.1.2: Based on the attack target characteristics, the attack timing characteristics, the attacked target characteristics, and the attack type characteristics, construct the target attack knowledge graph of the real-time computing power data.
5. The method according to claim 3, characterized in that, Step S3.2 includes: Step S3.2.1: For any candidate sample in the historical attack knowledge graph, perform temporal alignment based on the attack time sequence features of the candidate sample and the attack time sequence features of the target attack knowledge graph, and perform feature alignment based on the attack object features, attacked object features, and attack type features of the candidate sample and the attack object features, attacked object features, and attack type features of the target attack knowledge graph, respectively. Step S3.2.2: Determine candidate samples that match the target attack knowledge graph based on the temporal alignment results and feature alignment results.
6. The method according to claim 5, characterized in that, Step S3.2.1 includes: Step S3.2.1.1: According to the preset matching rules, match the attack object features of the candidate sample with the attack object features of the target attack knowledge graph to generate a first matching result; match the attacked object features of the candidate sample with the attacked object features of the target attack knowledge graph to generate a second matching result; and match the attack type features of the candidate sample with the attack type features of the target attack knowledge graph to generate a third matching result. Step S3.2.1.2: Generate the feature alignment result based on the first matching result, the second matching result, and the third matching result.
7. The method according to claim 1, characterized in that, Step S1 includes: Step S1.1: Extract features from the historical computing power data to obtain candidate features; Step S1.2: Perform clustering processing on the candidate features to generate at least one cluster, and perform semantic analysis on the cluster to generate semantic features corresponding to the cluster; Step S1.3: Match the semantic features with the existing attack features of the intelligent computing cloud platform, and filter out the semantic features that do not match successfully to obtain the hidden attack features.
8. The method according to claim 7, characterized in that, Step S1.3 includes: The unmatched semantic features are filtered based on a preset whitelist to obtain the hidden attack features.
9. A computing power anti-loss device for an intelligent computing cloud platform, characterized in that, include: The data acquisition module is used to collect historical computing power data of the intelligent computing cloud platform, and determine the core detection features and hidden attack features of the intelligent computing cloud platform based on the historical computing power data, as detection reference features; The detection module is used to perform known anomaly detection on the real-time computing power data of the intelligent computing cloud platform based on the detection reference features using a first detection engine to obtain a first detection result; to perform full attack chain malicious behavior detection on the real-time computing power data based on the detection reference features using a second detection engine to obtain a second detection result; and to perform intelligent computing cloud platform computing power scheduling and multi-tenant scenario abnormal behavior detection on the real-time computing power data based on the detection reference features using a third detection engine to obtain a third detection result. The source tracing module is used to trace the attack source based on the first detection result, the second detection result, and the third detection result to reconstruct the entire attack path; The processing module is used to perform computing power loss prevention processing on the intelligent computing cloud platform according to the entire attack path.
10. An electronic device, characterized in that, include: A processor, a memory, and a program stored in the memory and executable on the processor, wherein the program, when executed by the processor, implements the steps of the computing power loss prevention method of the intelligent computing cloud platform as described in any one of claims 1 to 8.
11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the computing power anti-loss method for the intelligent computing cloud platform as described in any one of claims 1 to 8.
12. A computer program product, characterized in that, It includes computer instructions, which, when executed by a processor, implement the steps of the computing power loss prevention method for the intelligent computing cloud platform as described in any one of claims 1 to 8.